Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disables Integrated Security in the ConnectionString when using SQL hosting integrations. #6839

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

danm-de
Copy link

@danm-de danm-de commented Nov 28, 2024

Disables the Integrated Windows Authentication when using Aspire.Hosting.SqlServer & Aspire.Hosting.Azure.Sql hosting integrations.

  • adds the Integrated Security=false parameter to the ConnectionString.

Description

Kerberos/Integrated Windows authentication is typically used in corporate environments. The SQL Management Studio remembers the last (successful) connection setting. As a developer, if I copy the connection string into the "Additional Connection Settings" tab and then click "Connect", I get an error message:

image

The additional parameter Integrated Security=false ensures that the SQL Management Studio uses the correct connection settings (authentication using username & password). The same probably applies to AzureSqlServer - but I couldn't test that.

Checklist

  • Is this feature complete?
    • Yes. Ready to ship.
    • No. Follow-up changes expected.
  • Are you including unit tests for the changes and scenario tests if relevant?
    • Yes (adapted the previous/existing tests)
    • No
  • Did you add public API?
    • Yes
      • If yes, did you have an API Review for it?
        • Yes
        • No
      • Did you add <remarks /> and <code /> elements on your triple slash comments?
        • Yes
        • No
    • No
  • Does the change make any security assumptions or guarantees?
    • Yes
      • If yes, have you done a threat model and had a security review?
        • Yes
        • No - I assume that the hosting image (and the connection string) will only be used in development and test environments.
    • No
  • Does the change require an update in our Aspire docs?

…r & Aspire.Hosting.Azure.Sql hosting integrations.

- adds the `Integrated Security=false` parameter to the ConnectionString.
@dotnet-policy-service dotnet-policy-service bot added the community-contribution Indicates that the PR has been added by a community member label Nov 28, 2024
@davidfowl
Copy link
Member

cc @IEvangelist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
community-contribution Indicates that the PR has been added by a community member
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants